Total
304758 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2001-0271 | 1 Mailnews.cgi | 1 Mailnews.cgi | 2008-09-05 | 10.0 HIGH | N/A |
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters. | |||||
CVE-2001-0292 | 1 Francisco Burzi | 1 Php-nuke | 2008-09-05 | 7.5 HIGH | N/A |
PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator. | |||||
CVE-2001-0305 | 1 Thinking Arts | 1 Es.one | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter. | |||||
CVE-2001-0308 | 1 Bajie | 1 Java Http Server | 2008-09-05 | 7.5 HIGH | N/A |
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program. | |||||
CVE-2001-0324 | 1 Microsoft | 2 Windows 2000, Windows 98 | 2008-09-05 | 2.6 LOW | N/A |
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash. | |||||
CVE-2001-0302 | 1 Pi3 | 1 Pi3web | 2008-09-05 | 5.0 MEDIUM | N/A |
Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL. | |||||
CVE-2001-0296 | 1 Texas Imperial Software | 1 Wftpd Pro | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. | |||||
CVE-2001-0283 | 1 Sun | 1 Sun Ftp | 2008-09-05 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT. | |||||
CVE-2001-0286 | 1 A1webserver | 1 Http Server | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | |||||
CVE-2000-0845 | 1 Digital | 1 Unix | 2008-09-05 | 6.4 MEDIUM | N/A |
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | |||||
CVE-2000-1118 | 1 24link | 1 24link | 2008-09-05 | 7.5 HIGH | N/A |
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request. | |||||
CVE-2000-1127 | 1 Hp | 1 Hp-ux | 2008-09-05 | 3.6 LOW | N/A |
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable. | |||||
CVE-2000-1177 | 1 Bb4 | 1 Big Brother Network Monitor | 2008-09-05 | 5.0 MEDIUM | N/A |
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter. | |||||
CVE-2000-0907 | 1 Etype | 1 Eserv | 2008-09-05 | 7.5 HIGH | N/A |
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands. | |||||
CVE-2000-1185 | 1 Itserv Incorporated | 1 Ridewaypn | 2008-09-05 | 5.0 MEDIUM | N/A |
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests. | |||||
CVE-2000-1201 | 1 Checkpoint | 1 Firewall-1 | 2008-09-05 | 5.0 MEDIUM | N/A |
Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264. | |||||
CVE-2000-1012 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.2 HIGH | N/A |
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. | |||||
CVE-2000-1110 | 1 Ibm | 1 Net.data | 2008-09-05 | 5.0 MEDIUM | N/A |
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program. | |||||
CVE-2000-1159 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 7.5 HIGH | N/A |
NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands. | |||||
CVE-2000-0985 | 1 Nevis Systems | 1 All-mail | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. |